EX294 Manage automation security and operations Practice Question
Which two actions are appropriate when configuring a custom execution environment for an automation controller job? (Choose two.)
⚠ Common exam trap
Watch out — candidates often confuse the `execution_environment_image` field (set in the controller UI or API) with a setting in the project's SCM, or they assume that custom execution environments must always be stored in a public registry, ignoring private registry options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Building the execution environment using ansible-builder
Option B is correct because ansible-builder is the supported tool for creating custom execution environments; it reads an execution-environment.yml definition file and produces a container image containing the required collections, Python packages, and system dependencies. Option E is correct because the execution environment image is defined by a Containerfile (or Dockerfile) that specifies the base image and installs the needed packages, which ansible-builder uses as its build input. Option A is incorrect because execution environments can be stored in private registries (e.g., automation hub, private container registries), not only public ones, and public-only storage is not a requirement. Option C is incorrect because execution_environment_image is configured on the job template or organization in the automation controller, not in the project's SCM repository. Option D is incorrect because using the default execution environment does not constitute configuring a custom execution environment, which is what the scenario requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Storing the execution environment in a public registry only
Why it's wrong here
Automation controller pulls execution environment images from private automation hub, registry.redhat.io or an internal registry; public-only storage ignores air-gapped and access-controlled deployments. It is tempting because public registries are convenient, but they cannot host organisation-specific, authenticated images.
- ✓
Building the execution environment using ansible-builder
Why this is correct
ansible-builder reads an execution environment definition and produces the container image that automation controller pulls to run jobs. It satisfies the requirement for a custom execution environment by assembling dependencies into a runnable image, rather than relying on the default image.
- ✗
Setting the execution_environment_image in the project's SCM
Why it's wrong here
The execution environment image is defined on the job template or in the automation controller's execution environment configuration, not in project SCM. It is tempting because SCM holds playbooks and inventories, but execution_environment_image is not a valid project-level variable.
- ✗
Using the default execution environment provided by controller
Why it's wrong here
The default execution environment ships with automation controller and lacks the collections, Python libraries or system packages a custom job requires. It is tempting as a zero-configuration baseline, but the question asks about configuring a custom execution environment, which the default cannot satisfy.
- ✓
Creating a Containerfile with the required packages
Why this is correct
The Containerfile declares the base image and installs the collections, Python packages and system dependencies the job needs. Writing it satisfies the custom execution environment requirement because ansible-builder consumes this file to construct the image.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX294 question from scratch — 392 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.